Skip Links

Top U.S. domain name registrars lag on DNS security

Registrars such as Network Solutions and Go Daddy haven't committed to launch dates for emerging Web security standard

By , Network World
March 23, 2010 11:35 AM ET

Network World - The leading domain name registrars in the United States appear to be dragging their feet on the deployment of DNS Security Extensions, an emerging standard that prevents an insidious type of hacking attack where network traffic is redirected from a legitimate Web site to a fake one without the Web site operator or user knowing.

DNSSEC prevents cache poisoning attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption. Cache poisoning attacks are possible because of a serious flaw in the DNS that was disclosed by security researcher Dan Kaminsky in 2008.

80% of government Web sites miss DNS security deadline

In order for Web site operators and end users to benefit from DNSSEC, the standard must be supported at every level of the DNS heirarchy.

At the top of this heirarchy, the DNS root servers will support DNSSEC on July 1.

Next are the registries that operate the back-end servers for the various top-level domains. The registries have announced rolling deadlines for their DNSSEC deployments: .org and .edu in June; .net in December; and .com by March 2011.
However, none of the top 10 domain name registrars in the United States has committed to a deadline for deploying DNSSEC.

"It's sad that the registrars are not keeping up with the registries in their deployment schedules for DNSSEC," says Paul Hoffman, director of the VPN Consortium and an active participant in DNSSEC standards development at the Internet Engineering Task Force. "If my registrar can't tell me when they will support DNSSEC, then I can't do the planning I need to do to upgrade my DNS software."

U.S. corporations -- such as banks and e-retailers -- won't be able to deploy the extra layer of security provided by DNSSEC until their registrars offer it as a service.

"It is a roadblock," Hoffman says. "If my registrar doesn't know how do to DNSSEC, I have to change registrars…Whichever registrar announces first is going to see people switching to them."

Of the 10 largest domain name registrars in the United States, only four responded to queries about the status of their DNSSEC deployments. None of these registrars would commit to a deadline for when they will support this new security mechanism.

Network Solutions and Dotster appear to be furthest along with DNSSEC.

"We are supportive of the DNSSEC initiative and recognize its technical importance and its efficiency in securing directory data," sais Network Solutions spokeswoman Susan Wade. "We are working closely with the registries and are actively engaged in market research to determine the demand for DNS Security. At the present time, we do not have a launch date for our DNSSEC offering."

"Dotster is working with a number of registries to implement DNSSEC," said Dotster's IT Director Aaron Bathum. "This is on our product road map, and availability is currently under review."

Go Daddy, the largest domain name registrar in the United States, was vague about its DNSSEC plans.

Our Commenting Policies
Latest News
rssRss Feed
View more Latest News